{"id":5720,"date":"2015-03-31T18:33:20","date_gmt":"2015-03-31T18:33:20","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=5720"},"modified":"2018-05-29T11:58:32","modified_gmt":"2018-05-29T11:58:32","slug":"supersource-fried-cookie-ltd-18-anti-virus-detection-rate-installcore","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/supersource-fried-cookie-ltd-18-anti-virus-detection-rate-installcore\/","title":{"rendered":"SuperSource (Fried Cookie Ltd.) &#8211; 18% Anti-Virus Detection Rate &#8211; InstallCore"},"content":{"rendered":"<p>Welcome! If you are a regular here on the FreeFixer blog you know that I&#8217;ve been looking on the certificates used to sign files that bundled various types of unwanted software. Today I found another certificate, used by a publisher called <strong>SuperSource (Fried Cookie Ltd.)<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-Fried-Cookie.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-5723\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-Fried-Cookie.png\" alt=\"SuperSource Fried Cookie\" width=\"488\" height=\"293\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-Fried-Cookie.png 488w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-Fried-Cookie-300x180.png 300w\" sizes=\"(max-width: 488px) 100vw, 488px\" \/><\/a><\/p>\n<p>You can see who the signer is when double-clicking on an executable file. SuperSource (Fried Cookie Ltd.) appears in the publisher field in the dialog that pops up. Information about a digital signature and the certificate can also be found under the Digital Signature tab.. The screenshot below shows the SuperSource (Fried Cookie Ltd.) certificate. From the certificate info we can see that SuperSource (Fried Cookie Ltd.) appears to be located in Israel.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-Fried-Cookie-Ltd.-cert.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-5721\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-Fried-Cookie-Ltd.-cert.png\" alt=\"SuperSource (Fried Cookie Ltd.) cert\" width=\"447\" height=\"441\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-Fried-Cookie-Ltd.-cert.png 447w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-Fried-Cookie-Ltd.-cert-300x295.png 300w\" sizes=\"(max-width: 447px) 100vw, 447px\" \/><\/a><\/p>\n<p>The reason I&#8217;m writing this blog post is that the SuperSource (Fried Cookie Ltd.) file is detected by many of the anti-virus software at <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a>. Avast detects installer_jdownloader_English.exe as <strong>Win32:Trojan-gen<\/strong>, AVG reports <strong>Generic.0C3<\/strong>, DrWeb reports <strong>Trojan.InstallCore.312<\/strong>, K7AntiVirus calls it <strong>Adware ( 004b91c91 )<\/strong> and VIPRE reports <strong>InstallCore (fs)<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-anti-virus-report.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-5722\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-anti-virus-report.png\" alt=\"SuperSource anti-virus report\" width=\"749\" height=\"428\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-anti-virus-report.png 749w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/SuperSource-anti-virus-report-300x171.png 300w\" sizes=\"(max-width: 749px) 100vw, 749px\" \/><\/a><\/p>\n<p>Did you also find a SuperSource (Fried Cookie Ltd.) file? What kind of download was it? If you remember the download link, please post it in the comments below.<\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome! If you are a regular here on the FreeFixer blog you know that I&#8217;ve been looking on the certificates used to sign files that bundled various types of unwanted software. Today I found another certificate, used by a publisher called SuperSource (Fried Cookie Ltd.). You can see who the signer is when double-clicking on &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/supersource-fried-cookie-ltd-18-anti-virus-detection-rate-installcore\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">SuperSource (Fried Cookie Ltd.) &#8211; 18% Anti-Virus Detection Rate &#8211; InstallCore<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/5720"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=5720"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/5720\/revisions"}],"predecessor-version":[{"id":5724,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/5720\/revisions\/5724"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=5720"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=5720"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=5720"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}